Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Infostealer

StealC

Infostealer 28 detections found

Also known as: Stealc, StealC V2, Stealc Stealer

StealC is a lightweight (~80KB) Windows information stealer that emerged on Russian-speaking underground forums (XSS, BHF) in January 2023, sold as malware-as-a-service by an actor using the handle "Plymouth" and modeled on Vidar, Raccoon, Mars, and RedLine. It is delivered via cracked-software sites and drive-by/phishing lures, and its file-grabber and stealer modules target credentials, cookies, and autofill data from 20+ browsers, 75+ browser extensions/crypto wallets, and apps like Discord, Telegram, and Steam. No law-enforcement disruption has been reported; the family remains actively maintained, with a StealC V2 update in 2024-2025 adding stealth and expanded data-theft features.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
snort ET TROJAN StealC v2 Fake 404 Page Observed rev 1 2025-04-22
suricata ET MALWARE StealC v2 Fake 404 Page Observed rev 1 2025-04-22
suricata ET MALWARE StealC v2 CnC Server Response rev 1 2025-04-11
snort ET TROJAN StealC v2 CnC Server Response rev 1 2025-04-11
snort ET TROJAN Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 rev 1 2025-01-17
suricata ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 rev 1 2025-01-17
suricata ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M2 rev 1 2024-03-28
snort ET TROJAN Win32/Stealc Active C2 Responding with browsers Config M1 rev 1 2024-03-28
snort ET TROJAN Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M3 rev 1 2024-03-28
snort ET TROJAN Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1 rev 1 2024-03-28
snort ET TROJAN Win32/Stealc Active C2 Responding with browsers Config M3 rev 1 2024-03-28
snort ET TROJAN Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M2 rev 1 2024-03-28
snort ET TROJAN Win32/Stealc Active C2 Responding with browsers Config M2 rev 1 2024-03-28
suricata ET MALWARE Win32/Stealc Active C2 Responding with browsers Config M2 rev 1 2024-03-28
suricata ET MALWARE Win32/Stealc Active C2 Responding with browsers Config M1 rev 1 2024-03-28
suricata ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M3 rev 1 2024-03-28
suricata ET MALWARE Win32/Stealc Active C2 Responding with browsers Config M3 rev 1 2024-03-28
suricata ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1 rev 1 2024-03-28
suricata ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1 rev 2 2024-03-14
suricata ET MALWARE Win32/Stealc Requesting plugins Config from C2 rev 2 2024-03-14
suricata ET MALWARE Win32/Stealc Requesting browsers Config from C2 rev 2 2024-03-14
snort ET TROJAN Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1 rev 1 2023-11-10
snort ET TROJAN Win32/Stealc Requesting plugins Config from C2 rev 1 2023-02-20
snort ET TROJAN Win32/Stealc Requesting browsers Config from C2 rev 1 2023-02-20
snort ET TROJAN [SEKOIA.IO] Win32/Stealc C2 Check-in rev 1 2023-02-20
suricata ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in rev 1 2023-02-20
suricata ET MALWARE Win32/Stealc Submitting Screenshot to C2 rev 1 2023-02-20
suricata ET MALWARE Win32/Stealc Submitting System Information to C2 rev 1 2023-02-20